Question: The Chief Information Security Officer ( CISO ) has outlined a five - year plan for the company that includes the following: - Implement an

The Chief Information Security Officer (CISO) has outlined a five-year plan for the company that
includes the following:
- Implement an application security program.
- Reduce the click rate on phishing simulations from 73% to 8%.
- Deploy EDR to all workstations and servers.
- Ensure all systems are sending logs to the SIEM.
- Reduce the percentage of systems with vulnerabilities from 89% to 5%.
Which of the following would BEST aid the CISO in determining whether these goals are
obtainable?
A. An asset inventory
B. A third-party audit
C. A risk assessment
D. An organizational CMMI

Step by Step Solution

There are 3 Steps involved in it

1 Expert Approved Answer
Step: 1 Unlock blur-text-image
Question Has Been Solved by an Expert!

Get step-by-step solutions from verified subject matter experts

Step: 2 Unlock
Step: 3 Unlock

Students Have Also Explored These Related Databases Questions!